CVE-2014-0151
published 2015-02-13CVE-2014-0151: Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests…
PriorityP428medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
0.64%
46.6th percentile
Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a REST API request.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | ovirt-engine | <= 3.5.0 | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-64m5-2h4c-p759: Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3
ghsa_unreviewed·2022-05-13
CVE-2014-0151 [MEDIUM] CWE-352 GHSA-64m5-2h4c-p759: Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3
Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a REST API request.
Red Hat
ovirt-engine: cross-site request forgery (CSRF)
vendor_redhat·2014-03-17·CVSS 6.8
CVE-2014-0151 [MEDIUM] CWE-352 ovirt-engine: cross-site request forgery (CSRF)
ovirt-engine: cross-site request forgery (CSRF)
Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a REST API request.
A Cross-Site Request Forgery (CSRF) flaw was found in the oVirt REST API. A remote attacker could provide a specially crafted web page that, when visited by a user with a valid REST API session, would allow the attacker to trigger calls to the oVirt REST API.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0151 ovirt-engine: cross-site request forgery (CSRF)
bugzilla·2014-03-28·CVSS 6.8
CVE-2014-0151 [MEDIUM] CVE-2014-0151 ovirt-engine: cross-site request forgery (CSRF)
CVE-2014-0151 ovirt-engine: cross-site request forgery (CSRF)
The oVirt REST API is vulnerable to Cross-Site Request Forgery (CSRF) attacks. A remote attacker could provide a specially-crafted web page that, when visited by a user with a valid REST API session, would allow the attacker to trigger calls to the oVirt REST API.
Discussion:
Upstream bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1077441
---
Created ovirt-engine tracking bugs for this issue:
Affects: fedora-all [bug 1081906]
---
Note that the same vulnerability affects the oVirt backend/GUI, as an attacker can also craft a request for the GWT RPC servlet using the same method.
---
This issue has been addressed in the following products:
RHEV Manager version 3.5
Via RHSA-2015:0158 https://rhn.redhat.com/errata/RHS
Bugzilla
CVE-2014-0151 ovirt-engine: ovirt-engine-api: cross-site request forgery (CSRF) [fedora-all]
bugzilla·2014-03-28·CVSS 6.8
CVE-2014-0151 [MEDIUM] CVE-2014-0151 ovirt-engine: ovirt-engine-api: cross-site request forgery (CSRF) [fedora-all]
CVE-2014-0151 ovirt-engine: ovirt-engine-api: cross-site request forgery (CSRF) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note:
2015-02-13
Published